Can the new Token Protection policy in Conditional Access be used for Azure Virtual Desktops?

Everett Crane 0 Reputation points
2023-08-28T11:40:40.85+00:00

From my understanding of this policy, the token is securely bound to the hardware to secure the account. That secured token checks the hardware before allowing access to Azure resources. Based on that understanding, using an Azure Virtual Desktop created from an Image Server would break that trust with each newly spawned host.

Is there a way to configure the Token Protection policy to work with AVD's?

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,178 questions
{count} votes

1 answer

Sort by: Most helpful
  1. vipullag-MSFT 21,186 Reputation points Microsoft Employee
    2023-09-05T16:12:11.9833333+00:00

    Hello Everett Crane

    Firstly, apologies for the delay in responding here. I checked with internal team on this ask.

    This is not officially supported. It would not work in pooled scenarios, as the user is not registering the session host as his device.

    Please raise feature request here so that the product team can check on this https://techcommunity.microsoft.com/t5/azure-virtual-desktop/bd-p/AzureVirtualDesktopForum

    Hope this helps.

    0 comments No comments